AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company has an on-premises data center connected to AWS through a Site-to-Site VPN. Applications on-prem must resolve the private Route 53 records of a VPC-based domain (corp.internal). Which configuration will enable name resolution without exposing the VPC to the internet?

  • Create a Route 53 Resolver outbound endpoint in the VPC and add a forwarding rule sending corp.internal queries to the on-premises DNS server.

  • Create a Route 53 Resolver inbound endpoint in the VPC and configure the on-premises DNS server with a conditional forwarder for corp.internal that points to the endpoint's IP addresses.

  • Associate the private hosted zone with the default VPC and update the VPC DHCP options set to use AmazonProvidedDNS.

  • Deploy an Interface VPC Endpoint for Route 53 and allow inbound TCP/UDP 53 from the data center.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot